Skip to content

Guard StatefulUrlAccessTokenProvider with a lock for standalone use - #365

Draft
skjolber wants to merge 4 commits into
masterfrom
wrapStatefulUrlAccessTokenProvider
Draft

skjolber wants to merge 4 commits into
masterfrom
wrapStatefulUrlAccessTokenProvider

Conversation

@skjolber

@skjolber skjolber commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

In most cases the above (wrapping) provider has a cache-with-lock mechanism already.

This makes extra sure that refresh tokens are not rotated and reused by a concurrent call.

Since there is a Lock we also need to pass a timeout so that nothing can block forever.

TODO: Better to create a generic wrapper and use it when appropriate?

@skjolber skjolber added the AI AI assisted label Sep 2, 2026
@skjolber
skjolber requested review from viliket and a balanced review from Copilot September 2, 2026 21:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Lock contention uses a stale timestamp for token validation and expiry calculations, and the concurrency behavior lacks tests.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds bounded synchronization to stateful token providers to prevent concurrent refresh-token reuse.

Changes:

  • Adds an internal timed refresh lock and configurable timeout.
  • Extends provider constructors while deprecating legacy signatures.
  • Improves scheduled-future visibility.
File summaries
File Description
AbstractStatefulUrlAccessTokenProvider.java Adds locking and timeout handling.
StatefulUrlAccessTokenProvider.java Adds timeout constructor.
AccessTokenProviderBuilder.java Supplies the default timeout.
PreemptiveCachedAccessTokenProvider.java Makes scheduled future volatile.
RestClientStatefulUrlAccessTokenProvider.java Adds timeout constructor.
RestClientJwtClientBeanDefinitionRegistryPostProcessorSupport.java Supplies the default timeout.
WebClientStatefulUrlAccessTokenProvider.java Adds timeout constructor.
WebfluxJwtClientBeanDefinitionRegistryPostProcessorSupport.java Supplies the default timeout.
RestTemplateStatefulUrlAccessTokenProvider.java Adds timeout constructor.
RestTemplateJwtClientBeanDefinitionRegistryPostProcessorSupport.java Supplies the default timeout.
Review details
  • Files reviewed: 10/10 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…ider

Co-authored-by: skjolber <1031478+skjolber@users.noreply.github.com>
@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@skjolber
skjolber marked this pull request as draft September 3, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI AI assisted

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants